Posts
2476
Following
561
Followers
1266
A drunken debugger

Heretek of Silent Signal
repeated
Edited 2 months ago

watchTowr: Veeam Backup & Response - RCE With Auth, But Mostly Without Auth (CVE-2024-40711)
Reference: CVE-2024-40711 (9.8 critical, disclosed 04 September 2024 by Veeam) Veeam Backup & Replication: A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). This vulnerability was reported by reported by Florian Hauser @frycos with CODE WHITE Gmbh @codewhitesec.

watchTowr doing what they do best, root cause analysis of vulnerabilities and breaking it down Barney style. Veeam Backup and Replication's CVE-2024-40711 has an authenticated RCE with a 9.8? watchTowr does patch-diffing (a lot of code and rambling). They name drop James Forshaw @tiraniddo in referencing “Stupid is as Stupid Does When It Comes to .NET Remoting”

Okay in reading through this, CVE-2024-40711 is actually comprised of two separate bugs. Veeam silently patched an improper authorization bug, then the deserialisation bug 3 months later. watchTowr claims that there is a way to bypass CVE-2024-40711 (details are still under embargo). They do not release a proof of concept due to the current situation and proclivity for ransomware actors to go after Veeam backups.

0
3
0
repeated
repeated

3 more weeks before my Windows Kernel Exploitation training at
Don't miss out! More info on contents -> https://www.hexacon.fr/trainer/halbronn/

0
2
0
repeated

Project Zero Bot

New Project Zero issue:

PowerVR: DEVMEMXINT_RESERVATION::ppsPMR references PMRs but does not lock their physical addresses

https://project-zero.issues.chromium.org/issues/42451698

CVE-2024-34747
0
2
0
repeated

Okay, I figured out the answer. When entering the kernel via syscall, the architecture/instruction sets %ss from the %cs value + 8. When entering the kernel via interrupt, %ss is 0.

0
1
1
[RSS] Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

https://www.thezdi.com/blog/2024/9/4/exploiting-exchange-powershell-after-proxynotshell-part-1-multivaluedproperty
0
0
1
[RSS] Race conditions in Linux Kernel perf events

https://binarygecko.com/race-conditions-in-linux-kernel-perf-events/
0
1
4
[RSS] “Unstripping” binaries: Restoring debugging information in GDB with Pwndbg

https://blog.trailofbits.com/2024/09/06/unstripping-binaries-restoring-debugging-information-in-gdb-with-pwndbg/
0
5
5
[RSS] BinSub: The Simple Essence of Polymorphic Type Inference for Machine Code

https://arxiv.org/abs/2409.01841
0
0
1
repeated

I finally got my copy of !

Impressive work by the new @phrack staff 💚

2
3
1
Redundancy in DB schemas seem like another footgun while using LLM's.

https://en.wikipedia.org/wiki/Boyce%E2%80%93Codd_normal_form
0
0
0
repeated

Greetings, Myth Lovers! In celebration of Monday's theme is beer an other inebriating beverages! Do you know a myth that features beer or a similar drink? Is the beer helpful or a hindrance? Tell us the myth and use the hashtag for boosts.

@mythology @folklore @TarkabarkaHolgy @juergen_hubert @curiousordinary @wihtlore @FairytalesFood @bevanthomas @FinnFolklorist @Godyssey @GaymerGeek @starrytimepod @ljwrites

0
3
0
repeated

Sometimes when people don't want an idea interrogated they arrange words around it like a moat. Construct intricate vocabularies that make it so you can only approach it from certain directions, never from the directions where it is weak to attack. Insist you use their vocabulary, debate on their terms. Sometimes I like to just walk directly into the moat. See, it's only ankle deep. This makes people upset. You're ignorant of the theory! No, I'm standing in the middle of it. It's just water dude

6
5
0
repeated
repeated
repeated

technomancy (turbonerd aspect)

ublock origin is great and so don't take this the wrong way but I've never understood why it doesn't have a they-live mode where instead of removing the ads altogether they get rendered as greyscale messages like "OBEY" / "CONSUME" / "DO NOT QUESTION AUTHORITY"

1
8
1
repeated

Crypto is holding Texas' independent electricity grid hostage for ransom, while the conservatives who run the state realize they've been duped by the big businesses they sidle up to.
https://www.economist.com/united-states/2024/08/27/why-texas-republicans-are-souring-on-crypto

6
12
0
Show older